Logo

    m365 compliance

    Explore "m365 compliance" with insightful episodes like "Insider Threats in Microsoft 365", "Co-Pilot and Misconfigured Permissions - A Looming Threat?", "EP22: Can You Trust Microsoft with Security?", "EP19: How to Sell Cybersecurity to the C-Suite" and "EP17: On-Prem Security vs Cloud Security" from podcasts like ""The Security Swarm: A Hornetsecurity Podcast", "The Security Swarm: A Hornetsecurity Podcast", "The Security Swarm: A Hornetsecurity Podcast", "The Security Swarm: A Hornetsecurity Podcast" and "The Security Swarm: A Hornetsecurity Podcast"" and more!

    Episodes (8)

    Insider Threats in Microsoft 365

    Insider Threats in Microsoft 365

    Join host Andy and special guest Philip Galea, R&D Manager at Hornetsecurity, as they explore insider threats within Microsoft 365. In this episode, the focus is on SharePoint Online and OneDrive for Business, shedding light on the nuances of insider threats and offering valuable insights on safeguarding against them. 

    Tune in for expert analysis and practical tips on fortifying your defenses and protecting your organization's sensitive data in the evolving landscape of cloud-hosted infrastructures. 

    Episode Resources:

    Effortlessly manage Microsoft 365 permissions 

    Co-Pilot and Misconfigured Permissions - A Looming Threat?

    Co-Pilot and Misconfigured Permissions - A Looming Threat?

    The use of Large Language Models (LLMs), like ChatGPT has skyrocketed, infiltrating multiple facets of modern life. In today's podcast episode, Andy and Paul Schnackenburg explore Microsoft 365 Co-Pilot and some surprising risks it can surface. Microsoft 365 Co-Pilot is more than just a virtual assistant: it's a powerhouse of productivity! It is a versatile generative AI tool that is embedded within various Microsoft 365 applications, and as such, it can execute various tasks across different software platforms in seconds. 

    Amidst discussions about Co-Pilot’s unique features and functionalities, many wonder: How does M365 Co-Pilot differ from other LLMs, and what implications does this hold for data security and privacy? Tune in to learn more!

    Timestamps:

    (4:16) – How is Co-Pilot different from other Large Language Models? 

    (11:40) – How are misconfigured permissions a special danger with Co-Pilot? 

    (16:53) – How do M365 tenant permission get so “misconfigured”? 

    (21:53) – How can your organization use Co-Pilot safely? 

    EP22: Can You Trust Microsoft with Security?

    EP22: Can You Trust Microsoft with Security?

    In this week’s episode, Andy and Paul have a discussion that has been brewing for the past several episodes. Microsoft has experienced a series of security incidents in the last few years. For example, the SolarWinds debacle in 2020, multiple exchange server on-prem issues, and more recently the Storm-0558 incident. 

    The core issue that all these problems raise, especially for a major global cloud provider, is trust. Can Microsoft be trusted to secure these services that millions around the globe use every single day? This is the main question that the guys get into in this episode along with lots of other great discussions around security in the Microsoft Cloud.  

    Timestamps:

    (1:55) – There has been a recent string of security issues at Microsoft 

    (6:42) – Storm-0558 

    (16:38) – Follow up on the SolarWinds attack from 2020 

    (20:50) – Multiple Exchange on-prem vulnerabilities over the last several years 

    (22:55) Power Platform cross-tenant un-authorized access 

    (26:61) – Communication seems to be a sore spot across all these issues 

    EP19: How to Sell Cybersecurity to the C-Suite

    EP19: How to Sell Cybersecurity to the C-Suite

    As cybersecurity professionals, MSSPs, and security vendors, we often get mired down in the weeds of the “tech” involved in the job and frequently struggle to convey the value of said technology to the C-Suite. With that said, we’re deviating from our regularly scheduled programming this week to bring you something of a “soft-skills” episode to address this key point 

    This week we’re excited to bring you the business and C-Suite knowledge of our very own Hornetsecurity Chief Operating Officer, Daniel Blank for a discussion on how you can get your leadership team to see value in technology, put priority on security, and ultimately sell cybersecurity to the C-Suite. Hope you enjoy! 

    Timestamps:

    2:23 Conveying the Value of Cybersecurity to Leadership without Using the Fear Angle 

    15:50 Compliance and Similar Issues Often Drives C-Suite Attention 

    26:05 An Example - What Would Daniel Look for When Having to Make a C-Suite Decision? 

    Episode Resources:

    365 Total Protection 

    Email Encryption 

    Andy on LinkedIn, Twitter or Mastodon 

    Daniel on LinkedIn 

    EP17: On-Prem Security vs Cloud Security

    EP17: On-Prem Security vs Cloud Security

    In today’s episode we have Eric Siron, Microsoft MVP, joining Andy for a discussion on the debated topic of On-Prem Security versus Cloud Security from a security standpoint. The digital landscape has transformed, raising questions about securing multiple cloud services, APIs, and the scattered user base. We explore how defenses have evolved and although default protections have strengthened, attack vectors have grown smarter with the growth of ransomware. Join us as we dissect these changes and their impact on modern security paradigms in an era where protection and adaptation are paramount. 

    Disclaimer: This episode was recorded just before news of the Microsoft breach hit the headlines. Thus, while some of the perspectives may seem momentarily misaligned due to the unfolding events, the core insights and conclusions drawn remain the same.  

    Timestamps:

    3:50 – What is the current state of on-premises infrastructure in terms of security?  

    12:37 – How does compliance factor into on-premises security? 

    21:12 – Is Infrastructure in the cloud more secure? 

    33:12 – Is “The Cloud” or “On-Premises” more secure? 

    Episode Resources:

    Monthly Threat Report - August 2023 

    Andy and Paul Discuss M365 Security

    Andy and Paul Discuss the Difficulty of Licensing Security Features in M365

    Hornetsecurity Ransomware Survey Findings

    The Backup Bible

    Hornetsecurity's Security Awareness Service

    Information on Recent SEC Announcement

    EP15: A Frank Discussion on Licensing M365 Security Features

    EP15: A Frank Discussion on Licensing M365 Security Features

    Join us for an insightful discussion on the topic of licensing Microsoft 365 security features. Microsoft Certified Trainer, Paul Schnackenburg, joins us once again to share his valuable insights on how M365 licensing practices have evolved and why they’ve become so complex. 

    In this episode Andy and Paul look at all the different ways native security features in M365 are licensed, what challenges come along with that process, how the process is confusing and more! This includes some discussion around how M365 licensing in general is flawed as well as how third-party software vendors help plug-in and do what they can to simplify this mess. 

    Timestamps:

    2:22 – O365 licensing vs M365 licensing 

    5:06 – Is the complexity in M365 licensing deliberate? 

    7:09 Licensing and security with M365 business 

    13:30 – Licensing and security in the M365 Enterprise SKUs 

    19:30 – What about the EMS Suite? 

    21:42 What are E5 Compliance and E5 Security? 

    28:05 – How can a 3rd party vendor help make licensing security features easier? 

    Episode Resources:

    SysAdmin Dojo Podcast Episode on General M365 Licensing 

    Andy and Paul’s M365 Compliance Webinar

    Defender for Endpoint

    Hornetsecurity Services

    Find Andy on LinkedInTwitter or Mastadon

    Find Paul on LinkedIn or Twitter

    EP14: The Permissions Management Nightmare in SharePoint Online

    EP14: The Permissions Management Nightmare in SharePoint Online

    We’re back for another episode with Philip Galea, R&D Manager at Hornetsecurity. In today’s episode, Andy and Philip discuss the frustrations and challenges IT admins face when managing permissions and sharing effectively in SharePoint Online 

    As more organizations embrace remote work, collaborate with external freelancers, and rely on tools like Microsoft Teams and emails for sharing files, the need to manage permissions has become crucial. Tune in to this episode to learn about the complexities of SharePoint and discover ways to regain control over your access management. 

    Timestamps:

    4:44 The problems with managing permissions in SharePoint Online 

    8:34 The ease of file sharing in M365 has created a problem. 

    11:16 Have SharePoint security capabilities just been “lifted and shifted” to the cloud? 

    14:43 The egregious problem with duplicate named SharePoint custom roles. 

    23:32 What should M365 admins be doing about this problem?  

    27:10 Behind the scenes with M365 Permission Manager by Hornetsecurity 

    Episode Resources:

    365 Permission Manager

    Introducing 365 Permission Manager – Webinar

    Find Andy on LinkedInTwitter or Mastadon

    Find Philip on LinkedIn

    EP12: What We Learned by Asking the Community About Compliance

    EP12: What We Learned by Asking the Community About Compliance

    Get ready for an eye-opening episode recorded live at Infosecurity Europe in London. In this episode, Andy and Matt Frye dissect the results of a comprehensive IT compliance survey conducted by Hornetsecurity. In the rapidly evolving digital landscape, maintaining IT compliance has become a pressing concern for businesses worldwide.  

    Tune in to explore the key findings from this survey, featuring insights from over 200 IT professionals representing diverse roles, regions, industries, and experience levels. 

    Timestamps:

    02:32 Compliance is a growing concern 

    03:52 – Do businesses see compliance as important? 

    06:24 The burden of compliance on IT teams

    12:08  How are businesses verifying compliance? 

    14:46 Trust in the cloud continues to be a problem for some organizations 

    17:00 – M365 administrators are struggling with compliance tools 

    20:57 – The cost of non-compliance 

    Episode Resources:

    IT Cybersecurity Compliance Survey 

    365 Permission Manager 

    Find Andy on LinkedInTwitter or Mastadon

    Find Matt on LinkedIn

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io